<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: howto://use TMG 2010 as the Exchange edge transport server</title> <atom:link href="http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/feed/" rel="self" type="application/rss+xml" /><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/</link> <description>lest the tubes become overfull</description> <lastBuildDate>Wed, 08 Feb 2012 15:03:00 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=</generator> <item><title>By: JRV</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2827</link> <dc:creator>JRV</dc:creator> <pubDate>Thu, 02 Feb 2012 18:06:32 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2827</guid> <description>Adding to Ed&#039;s comment, MS has done a good job of integrating EX Edge, TMG &amp; FPE, making it about as painless a mail hygiene solution as you could hope for. And it&#039;s the only anti-spam I&#039;m aware of that&#039;s integrated with Outlook&#039;s Safe Senders List, making it easy for users to manage their own whitelists. Unless you&#039;re already invested in another mail hygiene product and can&#039;t or don&#039;t want to change, definitely use Edge + TMG + FPE.</description> <content:encoded><![CDATA[<p>Adding to Ed&#8217;s comment, MS has done a good job of integrating EX Edge, TMG &amp; FPE, making it about as painless a mail hygiene solution as you could hope for. And it&#8217;s the only anti-spam I&#8217;m aware of that&#8217;s integrated with Outlook&#8217;s Safe Senders List, making it easy for users to manage their own whitelists. Unless you&#8217;re already invested in another mail hygiene product and can&#8217;t or don&#8217;t want to change, definitely use Edge + TMG + FPE.</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2825</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Thu, 02 Feb 2012 17:56:35 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2825</guid> <description>TMG email protection works fine by itself, but it does not have all the functionality of Forefront Protection for Exchange (FPE.)
If you want the full anti-X capabilities, you will want to install FPE. For example, TMG will protect your email servers from attacks against email services, but does not protect your users from malware within an email. See &lt;a href=&quot;http://www.microsoft.com/en-us/server-cloud/forefront/protection-for-exchange-server.aspx&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;this&lt;/a&gt; and &lt;a href=&quot;http://www.microsoft.com/en-us/server-cloud/forefront/threat-management-gateway-benefits.aspx&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;this&lt;/a&gt; for details. If you only want to protect your servers, TMG is enough. If you want to protect your users, you want FPE or other third party anti-x solution.
Ed</description> <content:encoded><![CDATA[<p>TMG email protection works fine by itself, but it does not have all the functionality of Forefront Protection for Exchange (FPE.)<br
/> If you want the full anti-X capabilities, you will want to install FPE. For example, TMG will protect your email servers from attacks against email services, but does not protect your users from malware within an email. See <a
href="http://www.microsoft.com/en-us/server-cloud/forefront/protection-for-exchange-server.aspx" target="_blank" rel="nofollow">this</a> and <a
href="http://www.microsoft.com/en-us/server-cloud/forefront/threat-management-gateway-benefits.aspx" target="_blank" rel="nofollow">this</a> for details. If you only want to protect your servers, TMG is enough. If you want to protect your users, you want FPE or other third party anti-x solution.<br
/> Ed</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2824</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Thu, 02 Feb 2012 17:50:48 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2824</guid> <description>Merz,
It is ok to have single TMG installation with EDGE on top of it, and to install EDGE after TMG is installed. That is fine and is what I did.
Ed</description> <content:encoded><![CDATA[<p>Merz,<br
/> It is ok to have single TMG installation with EDGE on top of it, and to install EDGE after TMG is installed. That is fine and is what I did.<br
/> Ed</p> ]]></content:encoded> </item> <item><title>By: Merz</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2822</link> <dc:creator>Merz</dc:creator> <pubDate>Thu, 02 Feb 2012 11:16:46 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2822</guid> <description>Hey Ed,thank you for your replyi don&#039;t want to deal with two (FE and BE) TMG servers, i have started this way but then i decided to go with one instance of TMGmy another concern is that is it ok to have single TMG installation with EDGE on top of it and to install EDGE after TMG is installed, or should start my installation from beginning and install EDGE and then TMGP.S. once again. i cannot get the same functional if edge installed in another box?i have another questions to you i will back to them later</description> <content:encoded><![CDATA[<p>Hey Ed,</p><p>thank you for your reply</p><p>i don&#8217;t want to deal with two (FE and BE) TMG servers, i have started this way but then i decided to go with one instance of TMG</p><p>my another concern is that is it ok to have single TMG installation with EDGE on top of it and to install EDGE after TMG is installed, or should start my installation from beginning and install EDGE and then TMG</p><p>P.S. once again. i cannot get the same functional if edge installed in another box?</p><p>i have another questions to you i will back to them later</p> ]]></content:encoded> </item> <item><title>By: jerome</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2820</link> <dc:creator>jerome</dc:creator> <pubDate>Thu, 02 Feb 2012 08:42:49 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2820</guid> <description>Hi there,we need to install Exchange Edge Transport and Forefront Protection 2010 for Exchange Server in order to have it function successfully as a SMTP gateway with full Email AV, Antispam and Malware protection? How about if we only implement TMG eMail policy does it work itself?thank you.</description> <content:encoded><![CDATA[<p>Hi there,</p><p>we need to install Exchange Edge Transport and Forefront Protection 2010 for Exchange Server in order to have it function successfully as a SMTP gateway with full Email AV, Antispam and Malware protection? How about if we only implement TMG eMail policy does it work itself?</p><p>thank you.</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2816</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Wed, 01 Feb 2012 15:05:37 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2816</guid> <description>Merz,
In your situation I would do exactly what I did in this post. I had my TMG up and running and just added Exchange Edge Transport on top of it, and it worked fine. If you don&#039;t want to do that, then
Internet-&gt;TMG external-&gt;TMG DMZ-&gt;Edge Transport
and publish the mail server role on the Edge Transport using the TMG publishing wizard.
Either way will work fine, and with FPE installed on your Edge, you will get all the protection it offers.
HTH
Ed</description> <content:encoded><![CDATA[<p>Merz,<br
/> In your situation I would do exactly what I did in this post. I had my TMG up and running and just added Exchange Edge Transport on top of it, and it worked fine. If you don&#8217;t want to do that, then<br
/> Internet->TMG external->TMG DMZ->Edge Transport<br
/> and publish the mail server role on the Edge Transport using the TMG publishing wizard.<br
/> Either way will work fine, and with FPE installed on your Edge, you will get all the protection it offers.<br
/> HTH<br
/> Ed</p> ]]></content:encoded> </item> <item><title>By: Merz</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2810</link> <dc:creator>Merz</dc:creator> <pubDate>Tue, 31 Jan 2012 15:36:12 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2810</guid> <description>Thank you for your effort creating this blog posts.this blog post stuck me in front of endless! -)i will copy my text from some forum. i hope i will get right answer hereI&#039;m setting up new company infrastructure and I need your expert support to clarify few things!What I had installed so far, Domain Infrastructure domain.root, Exchange 2010 with all roles on single box, TMG with 3 network cards (Internal, DMZ, External)I&#039;m stuck on my way of installing Exchange 2010 EDGE Server. I have planned to install EDGE server in DMZ as standalone machine and publish SMTP via TMG to Internet and setup EdgeSync to HUB in Internal network.After I have installed EDGE server on standalone machine in DMZ and I have run Microsoft Forefront Protection for Exchange setup. At this point I have found blog post where it&#039;s recommended to install EDGE server along with TMG on the single box to have ability to use all features of TMG email scanning. All other blogs discussing the same installation type and i even found instruction on MS site regarding this setupThis is really confused me.My first main questions is: Is it really necessary to install Exchange EDGE role on the same box where TMG installed to have ability use all functionality of email scanning?Another question is: What I will lose if I would install EDGE on separate box in DMZ behind protected by TMG?In addition: It’s highly recommended to install EDGE server first and then TMG.  But my TMG box is ready and don’t want to do configurations steps again
-------------------------------------------------------------------------------can i achieve all tmg email scanning featutures without installing EDGE role on TMG itself. i don&#039;t want to loadmy firewall and proxy for users with Exchange EDGE installationthank you</description> <content:encoded><![CDATA[<p>Thank you for your effort creating this blog posts.</p><p>this blog post stuck me in front of endless! -)</p><p>i will copy my text from some forum. i hope i will get right answer here</p><p>I&#8217;m setting up new company infrastructure and I need your expert support to clarify few things!</p><p>What I had installed so far, Domain Infrastructure domain.root, Exchange 2010 with all roles on single box, TMG with 3 network cards (Internal, DMZ, External)</p><p>I&#8217;m stuck on my way of installing Exchange 2010 EDGE Server. I have planned to install EDGE server in DMZ as standalone machine and publish SMTP via TMG to Internet and setup EdgeSync to HUB in Internal network.</p><p>After I have installed EDGE server on standalone machine in DMZ and I have run Microsoft Forefront Protection for Exchange setup. At this point I have found blog post where it&#8217;s recommended to install EDGE server along with TMG on the single box to have ability to use all features of TMG email scanning. All other blogs discussing the same installation type and i even found instruction on MS site regarding this setup</p><p>This is really confused me.</p><p>My first main questions is: Is it really necessary to install Exchange EDGE role on the same box where TMG installed to have ability use all functionality of email scanning?</p><p>Another question is: What I will lose if I would install EDGE on separate box in DMZ behind protected by TMG?</p><p>In addition: It’s highly recommended to install EDGE server first and then TMG.  But my TMG box is ready and don’t want to do configurations steps again<br
/> &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p><p>can i achieve all tmg email scanning featutures without installing EDGE role on TMG itself. i don&#8217;t want to loadmy firewall and proxy for users with Exchange EDGE installation</p><p>thank you</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2525</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Thu, 24 Nov 2011 11:36:16 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2525</guid> <description>Hi Harshal
Jeff must either stay up later, or get up earlier, because he beat me to it. He&#039;s quite correct.
Server and all SPs and patches
Then TMG
Then Exchange Edge Transport role
Then FPE
Ed</description> <content:encoded><![CDATA[<p>Hi Harshal<br
/> Jeff must either stay up later, or get up earlier, because he beat me to it. He&#8217;s quite correct.<br
/> Server and all SPs and patches<br
/> Then TMG<br
/> Then Exchange Edge Transport role<br
/> Then FPE<br
/> Ed</p> ]]></content:encoded> </item> <item><title>By: Jeff Vandervoort</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2523</link> <dc:creator>Jeff Vandervoort</dc:creator> <pubDate>Thu, 24 Nov 2011 06:08:15 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2523</guid> <description>Harshal, hate to tell you this, but TMG has to go on the machine before Exchange Edge. Follow the steps in the sequence in the article and you should be in good shape.</description> <content:encoded><![CDATA[<p>Harshal, hate to tell you this, but TMG has to go on the machine before Exchange Edge. Follow the steps in the sequence in the article and you should be in good shape.</p> ]]></content:encoded> </item> <item><title>By: Harshal</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2522</link> <dc:creator>Harshal</dc:creator> <pubDate>Thu, 24 Nov 2011 05:51:58 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2522</guid> <description>Dear Ed,
First of all, I would like to thank you for this article. It helped me a lot.I have installed TMG 2010 on Edge transport in a workgroup environment (not a domain member). First I installed Edge &amp; check my inbound &amp; outbound mail flow. It worked perfectly fine. Then I installed TMG on it &amp; configured Email policy. But then in TMg console under monitoring section, it says either Email configuration policy could not be applied as either Edge Transport or Forefront Protection for Exchange is not installed. So my question is, how did you get TMG &amp; its features for Email content filter work without FPE?Just FYI, I also installed FPE then but then TMG managed control serivce crashed &amp; cannot start. So next question is what is the correct order for all the three products towork properly? please correct me if I am wrong &amp; my approach is
1. Windows 2008 R2 Ent x64
2. AD LDS
3. Edge Transport Role
4. FPE
5. TMG 2010I did install as per the above order but still Email Policy cannot be applied but I can send &amp; receive emails without any issues.I would really appreciate your answers
Regards,Harshal</description> <content:encoded><![CDATA[<p>Dear Ed,<br
/> First of all, I would like to thank you for this article. It helped me a lot.</p><p>I have installed TMG 2010 on Edge transport in a workgroup environment (not a domain member). First I installed Edge &amp; check my inbound &amp; outbound mail flow. It worked perfectly fine. Then I installed TMG on it &amp; configured Email policy. But then in TMg console under monitoring section, it says either Email configuration policy could not be applied as either Edge Transport or Forefront Protection for Exchange is not installed. So my question is, how did you get TMG &amp; its features for Email content filter work without FPE?</p><p>Just FYI, I also installed FPE then but then TMG managed control serivce crashed &amp; cannot start. So next question is what is the correct order for all the three products towork properly? please correct me if I am wrong &amp; my approach is<br
/> 1. Windows 2008 R2 Ent x64<br
/> 2. AD LDS<br
/> 3. Edge Transport Role<br
/> 4. FPE<br
/> 5. TMG 2010</p><p>I did install as per the above order but still Email Policy cannot be applied but I can send &amp; receive emails without any issues.</p><p>I would really appreciate your answers<br
/> Regards,</p><p>Harshal</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2518</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Wed, 23 Nov 2011 19:05:14 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2518</guid> <description>Rock on! Thanks for letting us know.</description> <content:encoded><![CDATA[<p>Rock on! Thanks for letting us know.</p> ]]></content:encoded> </item> <item><title>By: Aaron</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2516</link> <dc:creator>Aaron</dc:creator> <pubDate>Wed, 23 Nov 2011 18:26:22 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2516</guid> <description>Thanks, it was indeed my network configuration, fixed that and also deleted an old entry in a hosts file on the mail server and i&#039;m good to go.  Thanks a lot guys.</description> <content:encoded><![CDATA[<p>Thanks, it was indeed my network configuration, fixed that and also deleted an old entry in a hosts file on the mail server and i&#8217;m good to go.  Thanks a lot guys.</p> ]]></content:encoded> </item> <item><title>By: JRV</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2509</link> <dc:creator>JRV</dc:creator> <pubDate>Mon, 21 Nov 2011 21:54:27 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2509</guid> <description>Spoofing errors occur when a packet arrives at an interface sent from an IP address OTHER THAN what TMG is expecting it on. Is the 5.x.x.x subnet in the definition for the Network?</description> <content:encoded><![CDATA[<p>Spoofing errors occur when a packet arrives at an interface sent from an IP address OTHER THAN what TMG is expecting it on. Is the 5.x.x.x subnet in the definition for the Network?</p> ]]></content:encoded> </item> <item><title>By: Ed Fisher</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2508</link> <dc:creator>Ed Fisher</dc:creator> <pubDate>Mon, 21 Nov 2011 21:53:53 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2508</guid> <description>I believe the most important clue is this one
&lt;blockquote&gt;The error I get keeps telling me that the source IP address is spoofed. The source IP is the same each time I see the error, but the source port seems to be different every time.&lt;/blockquote&gt;
Check your network definitions on the TMG to make sure what is EXTERNAL is properly defined. With a two-NIC setup, your internal address space should be internal, and that should NOT include your DMZ addresses. The error message comes from the TMG getting traffic from a source ip.addr that is associated with a different zone. So if your DMZ subnet is included in the ranges of the INTERNAL network, and traffic from a DMZ ip.addr hits the NIC on the TMG associated with the external network, TMG flags it as spoofed. Since your source is a RIPE network, but we know it is your Edge server in your DMZ, I am pretty sure your network definitions are borked.TMG Console
Networking
Network tab
confirm the ip.addrs in the Internal network...everything else (DMZ and Internet) is external.Let me know if that fixes it for you.
Ed</description> <content:encoded><![CDATA[<p>I believe the most important clue is this one</p><blockquote><p>The error I get keeps telling me that the source IP address is spoofed. The source IP is the same each time I see the error, but the source port seems to be different every time.</p></blockquote><p>Check your network definitions on the TMG to make sure what is EXTERNAL is properly defined. With a two-NIC setup, your internal address space should be internal, and that should NOT include your DMZ addresses. The error message comes from the TMG getting traffic from a source ip.addr that is associated with a different zone. So if your DMZ subnet is included in the ranges of the INTERNAL network, and traffic from a DMZ ip.addr hits the NIC on the TMG associated with the external network, TMG flags it as spoofed. Since your source is a RIPE network, but we know it is your Edge server in your DMZ, I am pretty sure your network definitions are borked.</p><p>TMG Console<br
/> Networking<br
/> Network tab<br
/> confirm the ip.addrs in the Internal network&#8230;everything else (DMZ and Internet) is external.</p><p>Let me know if that fixes it for you.<br
/> Ed</p> ]]></content:encoded> </item> <item><title>By: Aaron</title><link>http://retrohack.com/how-to-use-tmg-2010-as-the-exchange-edge-transport-server/comment-page-1/#comment-2507</link> <dc:creator>Aaron</dc:creator> <pubDate>Mon, 21 Nov 2011 21:34:38 +0000</pubDate> <guid
isPermaLink="false">http://retrohack.com/howtouse-tmg-2010-as-the-exchange-edge-transport-server/#comment-2507</guid> <description>Great articles regarding TMG and exchange, best I&#039;ve found in my attempts to google for answers.I&#039;m wondering if you have any ideas that could help me out, I&#039;m in the banging my head against the desk stage of my troubleshooting.My setup:  single mail server in LAN with CAS role, edge server in DMZ with TMG 2010 double NIC&#039;s, domain joined on one NIC and DMZ on the other.I&#039;ve run through all of your TMG publishing setups and i have green boxes for all connection tests for OWA and etc.  I also had a successful edgesubscription between my mail server and my mail edge server and I have been sending and receiving mail successfully for months, until I installed TMG 2010.I made a firewall policy rule that allows “LDAPS (EdgeSync)”  between my hub transport and local host like JRV mentions before trying to make a new edgesubscription.  When I run the command from powershell as administrator &quot;start-edgesubscription&quot; from my CAS, I get the following error:  &quot;could not connect LDAP server is unavailable&quot;.  My TMG 2010 log, shows that it denied a connection from my mail server to my mailedge server for the LDAPS protocol on port 50636, even though i made a rule that allows LDAPS(EdgeSync) and LDAP between the exact IP&#039;s that it shows it has denied.  For troubleshooting purposes I have allowed LDAPS from pretty much every source I can think of, explicitly put the IP&#039;s in the rule that the log says are the source and destination, as well as internal, external, and etc.The error I get keeps telling me that the source IP address is spoofed.  The source IP is the same each time I see the error, but the source port seems to be different every time.Error:Denied Connection MAILEDGE 11/21/2011 2:08:22 PM
Log type: Firewall service
Status: A packet was dropped because Forefront TMG determined that the source IP address is spoofed.
Rule: None - see Result Code
Source: Internal (5.0.0.212:14050)
Destination: Local Host (10.10.10.12:50636)
Protocol: LDAPS(EdgeSync)
Additional information
Number of bytes sent: 0 Number of bytes received: 0
Processing time: 0ms Original Client IP: 5.0.0.212
Any ideas?</description> <content:encoded><![CDATA[<p>Great articles regarding TMG and exchange, best I&#8217;ve found in my attempts to google for answers.</p><p>I&#8217;m wondering if you have any ideas that could help me out, I&#8217;m in the banging my head against the desk stage of my troubleshooting.</p><p>My setup:  single mail server in LAN with CAS role, edge server in DMZ with TMG 2010 double NIC&#8217;s, domain joined on one NIC and DMZ on the other.</p><p>I&#8217;ve run through all of your TMG publishing setups and i have green boxes for all connection tests for OWA and etc.  I also had a successful edgesubscription between my mail server and my mail edge server and I have been sending and receiving mail successfully for months, until I installed TMG 2010.</p><p>I made a firewall policy rule that allows “LDAPS (EdgeSync)”  between my hub transport and local host like JRV mentions before trying to make a new edgesubscription.  When I run the command from powershell as administrator &#8220;start-edgesubscription&#8221; from my CAS, I get the following error:  &#8220;could not connect LDAP server is unavailable&#8221;.  My TMG 2010 log, shows that it denied a connection from my mail server to my mailedge server for the LDAPS protocol on port 50636, even though i made a rule that allows LDAPS(EdgeSync) and LDAP between the exact IP&#8217;s that it shows it has denied.  For troubleshooting purposes I have allowed LDAPS from pretty much every source I can think of, explicitly put the IP&#8217;s in the rule that the log says are the source and destination, as well as internal, external, and etc.</p><p>The error I get keeps telling me that the source IP address is spoofed.  The source IP is the same each time I see the error, but the source port seems to be different every time.</p><p>Error:</p><p>Denied Connection MAILEDGE 11/21/2011 2:08:22 PM<br
/> Log type: Firewall service<br
/> Status: A packet was dropped because Forefront TMG determined that the source IP address is spoofed.<br
/> Rule: None &#8211; see Result Code<br
/> Source: Internal (5.0.0.212:14050)<br
/> Destination: Local Host (10.10.10.12:50636)<br
/> Protocol: LDAPS(EdgeSync)<br
/> Additional information<br
/> Number of bytes sent: 0 Number of bytes received: 0<br
/> Processing time: 0ms Original Client IP: 5.0.0.212</p><p>Any ideas?</p> ]]></content:encoded> </item> </channel> </rss>
<!-- Served from: retrohack.com @ 2012-02-09 10:18:30 by W3 Total Cache -->
